Linksys CherryBlossom Advisory
linksys.com
linksys.com
Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying that it updated?
The firmware implant (aka flytrap) reproduces all of the router's normal functionality. On page 122 of the cherryblossom docs, it says that the firmware upgrade feature is implemented normally by the flytrap, and that if a user attempts to upgrade their router's firmware, it will overwrite the flytrap firmware.
Without a sample of the implant or confirmation from the CIA that the documents are legitimate & unaltered, this advisory is pretty much all we can do for those users.
Or: the CIA leaked it intentionally as smoke-screen.
I don't know. Are there organisational silos within intelligence agencies? Layers of access? It's hard to know for sure, but I'm yet to see a human organisation that doesn't have political in-fighting.
Because if they don't have this, then this is bad security advice against what is considered a targeted attack.
--
[1] Even though most users have no idea the management interface even exists.
I always disable it, but I'll bet I'm something like 1:10k in that respect.
What would make them believe that? Wish they had a detection tool as well. Anyone know of one?
I haven't played with it much, but there are ways to persist after a reset on Android, I'd assume the same is possible here. Very happy to be corrected.
Anyone know what the cheapest Linksys I could buy is, and whether these vulnerabilities have been released publicly?
To be clear, the main "vulnerability" is just ability to get physical access and re-flash the devices with a custom firmware which allows the access to the target network. The best defense would be locking down the router physically and setting a strong password for the admin portal.
There were no vulnerabilities included in the cherryblossom leak. The firmware implant deployment instructions included in the leak don't mention using any vulnerabilities either.
Almost all of the devices listed in the cherryblossom leak are not being sold anymore.
Another option is to setup a vpn server that all your devices connect to to access the internet. In that scenario it won't matter if your router is compromised because all traffic flowing through would be encrypted.
Nevermind the community, when it comes to vaguely complex things like IPTV and similar, support is either legacy or gone.
At this point OpenWRT is the only sane choice, at least it doesn't run everything as root and isn't going to shove off Multicast UDP packet forwarding support in the next year or two.
Probably your cheapest bet on the supported device list (ca. p27 of the PDF on Wikileaks) would be a WRT54G v5. The GL models have some support as well, but last I checked they had a relatively high used value, presumably for their hackability - the G models are much more limited.
(And the latest available is newer than what's on my router now, so might as well.)
If you have any information about RCEs, Cherryblossom details we may have missed, or any other vulnerabilities in Linksys devices, please email me directly at benjamin.samuels at belkin.com
If I understood things correctly, the Cherryblossom thing is a firmware and while this particular leak didn't mention any new RCEs I am surprised a bit that the possibility of using any other RCE was categorically ruled out by the wording of the advisory.